Splunk Enterprise

Knowledge Bundle (Searchpeer Bundle)- Replication Blacklist

mintutivo
Loves-to-Learn Lots

Due to some Performance Issues, Lookup/Dashboard failures, search failures and taking longtime to execute the searches. we have done some troubleshooting and come up with some exclusion list which needs to be blacklist. here I have few questions

1. how to blacklist these exclusion list? what will be the process and procedure that needs to be followed?
2. where should we blacklist? should we create any global App? is there any specific App or place to do this?

3. most of these are .csv files, Bin and Jar files.

I could see few splunk community answers, but I couldn't see any complete process or any procedure to follow.

Thanks in Advance, Appreciate your help!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Perhaps the manual at https://docs.splunk.com/Documentation/Splunk/8.2.0/DistSearch/Limittheknowledgebundlesize#Eliminate_...will help.  The files to exclude from replication go in the [replicationBlacklist] stanza, which is similar to the [replicationWhitelist] stanza that is described in greater detail in the same manual.  The settings can go into any app, but apply to ALL apps so be careful.

---
If this reply helps you, Karma would be appreciated.
0 Karma

mintutivo
Loves-to-Learn Lots

Hi Rich,

Thanks for providing the info. apart from that, I have few concerns here!

Should I create any App, and add these attributes/values to it (Replication Blacklist)?

OR 

can we Blacklist directly in Distsearch.conf (from /opt/splunk/etc/system/local on Search Head)?

 

please provide me any such info.

Thanks,

0 Karma

richgalloway
SplunkTrust
SplunkTrust

You can do it either way.  Since the changes affect all apps, I suggest putting the blacklist in etc/system/local.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...